CVE-2024-0384: WP Recipe Maker <= 9.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Recipe Notes
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Notes in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0384?
CVE-2024-0384 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting.
How do I fix CVE-2024-0384?
To fix CVE-2024-0384, update the WP Recipe Maker plugin to version 9.1.1 or later where the vulnerability is patched.
Who is affected by CVE-2024-0384?
CVE-2024-0384 affects users of the WP Recipe Maker plugin for WordPress up to and including version 9.1.0.
What type of attack does CVE-2024-0384 enable?
CVE-2024-0384 enables stored cross-site scripting attacks, allowing authenticated attackers to inject malicious scripts.
What versions of WP Recipe Maker are vulnerable to CVE-2024-0384?
All versions of WP Recipe Maker up to and including 9.1.0 are vulnerable to CVE-2024-0384.